MEDIUM 5.8 GitHub

CVE-2026-73607

SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check

### Summary `/api/storage/getOutlineStorage` is registered with `CheckAuth` only and performs no authorization of any kind. Given a document identifier it returns that document's stored outline state, regardless of the document's publish tier. The two write endpoints for the same data, `setOutlineStorage` and `removeOutlineStorage`, both carry `CheckAdminRole` and `CheckReadonly`. Only the read path is unguarded. ### Details **Routes.** `kernel/api/router.go:103` on master, `:108` on the dev

Affected Products

References

Published: 2026-10-01 · Source: GitHub · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-01 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.